Privacy Policy

Last updated: 2026-09-08

1. Overview

Dynamite Docs (“Dynamite Docs”, “we”, “us”, or “our”) operates an AI document extraction workspace that turns business documents, such as PDFs, scans, images, Word and Excel files, into structured data. This Privacy Policy explains what information we collect, why we collect it, how it is used, who it is shared with, and the choices and rights you have. By using the Service, you agree to the collection and use of information as described here. Your data stays yours.

2. Information we collect

  • Account information. When you sign in, we receive identifying details from your sign-in provider, such as your email address, name, and a unique identifier used to keep your account separate from others.
  • Documents and extraction results. The files you upload and the structured data (extracted fields, tables, and values) derived from them. This is the core of the Service and is processed only to perform the extraction you request.
  • Your API keys. If you connect your own AI provider keys (Bring-Your-Own-Key), we store an encrypted copy so the Service can route your extraction requests (see “Your API keys” below).
  • Billing information. When you purchase a paid plan, payment is handled by Creem or PayGlocal. We receive the payment status, plan, billing term, and provider transaction references, but we do not store or process your full payment card details.
  • Usage and technical data. Basic diagnostics such as page views, extraction success or failure, file type and size, provider used, model latency, and error logs, used to keep the Service reliable and to understand feature usage.

3. How we use your information

The general purposes in this section do not apply to information received from Google Workspace APIs. We use Google Workspace API data only for the user-facing Google Drive and Google Sheets features described in Section 4.

  • To provide, operate, and maintain the Service, including performing the extraction you request.
  • To route documents to the AI provider you select or to the default provider for processing.
  • To authenticate you, enforce plan limits and fair-use quotas, and provide billing and account management.
  • To save your corrections and patterns so repeated layouts get more accurate over time.
  • To monitor performance, detect abuse, and keep the Service secure and available.
  • To communicate with you about the Service, including transactional notices and support responses.

We never sell your data. We never use your documents to train foundation models.

4. Google Workspace API data

If you connect Google Drive or Google Sheets, Dynamite Docs uses information received from Google Workspace APIs only to provide the Google features you choose. Our use of this information complies with the Google API Services User Data Policy, including its Limited Use requirements.

  • Data we access. With your consent, we access the names, folder locations, file types, sizes, and modified dates needed to display Drive files through Google Picker; the contents of Drive files you select for import; and the spreadsheets, folders, and export files that you ask Dynamite Docs to create or update. We request the per-file drive.file permission for these tasks. We do not scan your entire Drive or download a file until you select it for import.
  • How we use it. We use Google user data to show the connected account, let you browse and search Drive, import the Drive files you select, extract structured data from a selected file, create Drive folders and export files, and create or update spreadsheets with extraction results. These are visible features that you start from the Dynamite Docs interface. We do not use Google user data for general analytics, marketing, pattern libraries shared between users, or any unrelated product purpose.
  • Storage and protection. We encrypt Google OAuth access and refresh tokens at rest with AES-256-GCM and use TLS in transit. We retain the granted scopes, token expiry, and last-used spreadsheet identifier so the connection works without a new authorization each time. Imported file copies and extraction results follow the storage and retention rules in Section 10.
  • Sharing. When you select a Drive file and start extraction, we send its contents only to an eligible AI provider shown for that extraction and only to produce the requested result. Google Drive imports always require a provider that does not train on submitted content, even when Privacy mode is off. Providers that may train on submitted content are not eligible for Google-sourced documents. Our contracted cloud infrastructure processes encrypted credentials and any Google-sourced files or results you choose to store. Dynamite Docs personnel do not read Google user data unless you explicitly ask for support involving specific data, access is necessary to investigate abuse or a security incident, or access is required by law. We do not otherwise transfer or disclose Google user data.
  • Prohibited uses. We do not sell Google user data or transfer it to data brokers or information resellers. We do not use it for advertising, including targeted, personalized, retargeted, or interest-based advertising. We do not use it to determine creditworthiness or for lending. We do not use it to create databases unrelated to the features you request. We do not use it to develop, train, or improve non-personalized or generalized AI or machine-learning models, and we do not allow our service providers or AI providers to do so.
  • Disconnecting and deletion. Disconnecting Google Drive and Sheets revokes the Google authorization and deletes the stored OAuth tokens and connection record from Dynamite Docs. Disconnecting does not automatically delete files you previously imported or extraction results you created because you may want to keep them. You can delete those items from the workspace before or after disconnecting, or request account and data deletion by emailing info@dynamitedocs.com.

If we materially change how we access, use, store, or share Google user data, we will update these disclosures and obtain your affirmative consent before the new use begins.

5. How your documents are processed

Files stay in your browser on Try free for 28 Days. On Hobby, Pro, and Ultra, uploaded files may be stored within the plan cloud allowance (via Cloudflare R2) so they survive refresh and devices. Files are sent to the AI provider you select (or the default provider) solely to perform the extraction you requested. The extracted fields, confidence scores, and your review corrections are stored so you can review, export, and reuse them.

When you connect your own API keys, your documents are sent only to the providers you chose, under those providers’ terms and privacy policies. Sensitive Documents mode blocks training-permitted providers by default, and policy controls let you restrict processing by data residency and training policy (including an EU-only processing option).

On Hobby, Pro, and Ultra, the optional Ollama companion sends document bytes from your browser to a signed, loopback-only service on your machine and performs model inference there instead of calling an external model provider. Account, workspace, and token issuance remain part of the hosted Service.

6. Your API keys

Provider keys you connect are encrypted at rest (AES-256-GCM) and are never sent to your browser or written to logs. Keys are used only to authenticate your extraction requests to the provider you chose. You can remove a key at any time from the AI settings panel, which deactivates it immediately.

7. Legal bases (GDPR)

Where the EU General Data Protection Regulation (GDPR) or the UK GDPR applies, we rely on the following legal bases:

  • Performance of a contract To provide the Service you asked for and to manage billing.
  • Legitimate interests To secure the Service, prevent abuse, and improve reliability.
  • Consent Where required for non-essential analytics or marketing, which you may withdraw at any time.
  • Legal obligation Where we must retain records to comply with applicable law.

8. Sharing and third parties

We share information only as needed to run the Service:

  • AI providers Except for Google Workspace API data, which is governed exclusively by Section 4, Gemini, Mistral, OpenAI, Anthropic, Groq, OpenRouter, Cloudflare, Nvidia, Cerebras, OVHcloud, GitHub, Zhipu, Hugging Face, SambaNova, Together, Moonshot, Fireworks, Cohere, Azure OpenAI, AWS Bedrock, xAI, Vertex AI, and custom OpenAI-compatible endpoints receive documents solely to perform the extraction you request. Most of these providers do not train on submitted content. Providers that may, including Gemini, OpenRouter, and custom endpoints, are excluded from default routing and are blocked by Sensitive Documents mode unless you explicitly enable them for non-Google documents. Google Workspace API data remains subject to the Limited Use restrictions in Section 4 regardless of other provider settings.
  • Creem Our Merchant of Record for subscription billing and payments.
  • PayGlocal Our payment gateway for hosted INR checkout and an optional international recurring checkout.
  • Cloud infrastructure (hosting providers) run the Service and store extraction data.
  • Product analytics Privacy-respecting, aggregated usage data that does not contain your documents.

Our Data Processing Agreement, which applies when we process personal data on your behalf, is at dynamitedocs.com/dpa.

We do not sell or rent your personal information or documents to anyone. We may disclose information if required by law, to enforce our Terms, or to protect the rights, property, or safety of Dynamite Docs, our users, or others.

9. International data transfers

Documents may be processed by AI providers and infrastructure located outside your country of residence. When we transfer personal data outside the EEA or the UK, we rely on appropriate safeguards such as Standard Contractual Clauses or an adequacy decision. On Pro and Ultra, an EU-only processing policy restricts eligible provider routing; the local Ollama companion is a separate on-device inference path on Hobby, Pro, and Ultra.

10. Storage, retention & deletion

  • Data is encrypted in transit (TLS) and at rest.
  • Files on Try free for 28 Days are processed in your browser and are not stored on our servers. On Hobby, Pro, and Ultra, uploaded files may be stored within the plan cloud allowance (Cloudflare R2) while your account is active. Extraction results are retained while your account is active and are removed when you delete them or request deletion.
  • You may delete files individually from your workspace at any time.
  • You can request deletion of your documents and account at any time by emailing info@dynamitedocs.com. We will delete or anonymize your data within 30 days, except where we must retain records to comply with law.

11. Cookies & analytics

We use essential cookies and local storage for sign-in and to remember your session and preferences. These are strictly necessary and do not require consent. We rely on legitimate interests for privacy-respecting, aggregated usage diagnostics (such as extraction success and feature usage) that never contain your documents or documents’ contents.

Session replay, recordings that help us diagnose errors, is non-essential and is enabled only after you accept it in the consent banner you will see on your first visit. You can change your preference at any time from the “Cookie settings” link in the footer of any page, and rejecting it will not affect the core functionality of the Service. We never sell your data.

12. Security

We apply industry-standard safeguards including encryption in transit and at rest, encrypted storage of API keys, strict access controls on production systems, and standard security headers on the Service. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for protecting your account credentials and for reviewing extracted data before relying on it.

13. Your rights

Where applicable law grants you rights (including under the GDPR and the California Consumer Privacy Act and similar US state laws), you may have the right to:

  • Access the personal information we hold about you.
  • Request correction of inaccurate information.
  • Request deletion or erasure of your personal information.
  • Restrict or object to certain processing.
  • Receive a portable copy of your data.
  • Withdraw consent where processing is based on consent.

To exercise any of these rights, email info@dynamitedocs.com. We will respond within the time period required by applicable law. If you are in the EEA or the UK and believe your data has been mishandled, you may also lodge a complaint with your local supervisory authority.

14. Children’s privacy

The Service is intended for business and professional use and is not directed to children under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.

15. Changes to this policy

We may update this Privacy Policy as the Service evolves. Material changes will be posted on this page with a revised “Last updated” date, and where required we will notify you by email or in-app notice. Your continued use of the Service after changes take effect constitutes acceptance of the revised policy.

16. Contact

Privacy questions or data requests: info@dynamitedocs.com.

Open the Dynamite Docs app or return to the homepage.

Loading Dynamite Docs… This page is taking longer than expected. Reload page.